Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2024-9098

Опубликовано: 14 нояб. 2024
Источник: oracle-oval
Платформа: Oracle Linux 9

Описание

ELSA-2024-9098: skopeo security update (MODERATE)

[2:1.16.1-1]

[2:1.16.0-1]

[2:1.15.2-1]

[2:1.15.1-1]

[2:1.15.0-1]

[2:1.14.3-0.1]

[2:1.14.1-2]

  • Switch to the maint branch
  • Related: Jira:RHEL-2112

[2:1.14.1-1]

[2:1.14.0-1]

  • bump to v1.14.0
  • Related: Jira:RHEL-2112

[2:1.13.3-3]

  • Rebuild with golang 1.20.10
  • Related: Jira:RHEL-2786

[2:1.13.3-2]

  • Rebuild with golang 1.21.3
  • Related: Jira:RHEL-2786

[2:1.13.3-1]

[2:1.13.2-1]

[2:1.13.1-1]

[2:1.13.0-1]

[2:1.12.0-3]

  • rebuild for following CVEs: CVE-2022-41724 CVE-2022-41725 CVE-2023-24537 CVE-2023-24538 CVE-2023-24534 CVE-2023-24536 CVE-2022-41723 CVE-2023-24539 CVE-2023-24540 CVE-2023-29400
  • Resolves: #2179967
  • Resolves: #2187323
  • Resolves: #2187384
  • Resolves: #2203703
  • Resolves: #2207523

[2:1.12.0-2]

  • remove fakeroot from skopeo-tests
  • Related: #2176063

[2:1.12.0-1]

  • update to 1.12.0
  • Related: #2176063

[2:1.11.3-0.1]

[2:1.11.2-0.2]

[2:1.11.2-0.1]

[2:1.11.1-1]

[2:1.11.0-1]

  • update to 1.11.0 release
  • Related: #2124478

[2:1.11.0-0.4]

[2:1.11.0-0.3]

[2:1.11.0-0.2]

[2:1.11.0-0.1]

[2:1.10.0-1]

[2:1.9.3-1]

Обновленные пакеты

Oracle Linux 9

Oracle Linux aarch64

skopeo

1.16.1-1.el9

skopeo-tests

1.16.1-1.el9

Oracle Linux x86_64

skopeo

1.16.1-1.el9

skopeo-tests

1.16.1-1.el9

Связанные уязвимости

oracle-oval
7 месяцев назад

ELSA-2024-9097: buildah security update (MODERATE)

oracle-oval
7 месяцев назад

ELSA-2024-9102: podman security update (MODERATE)

oracle-oval
7 месяцев назад

ELSA-2024-9115: grafana security update (MODERATE)

CVSS3: 8.3
ubuntu
около 1 года назад

A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing resource exhaustion, local path traversal, and other attacks.

CVSS3: 8.3
redhat
около 1 года назад

A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing resource exhaustion, local path traversal, and other attacks.

Уязвимость ELSA-2024-9098